SourceCodester Yoga Class Registration System Status Update update_status.php sql injection
CVE-2023-0980
9.8CRITICAL
Summary
A vulnerability has been identified in SourceCodester's Yoga Class Registration System, specifically within the Status Update Handler component found in the admin/registrations/update_status.php file. This vulnerability arises from improper handling of the 'id' argument, allowing for potential SQL injection attacks. Attackers may exploit this vulnerability remotely, manipulating SQL queries to gain unauthorized access to sensitive data or execute malicious commands.
Affected Version(s)
Yoga Class Registration System 1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
mroz1l (VulDB User)